4.3
CVSSv2

CVE-2012-6505

Published: 24/01/2013 Updated: 29/01/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote malicious users to inject arbitrary web script or HTML via the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

shawn bradley php volunteer management 1.0.2

Exploits

# Exploit Title: PHP Volunteer Management 'id' 102 Multiple Vulnerabilities # Date: 04/21/12 # Author: G13 # Twitter: @g13net # Software Site: sourceforgenet/projects/phpvolunteer/ # Version: 102 # Category: webapp (php) # ##### ToC ##### 0x01 Description 0x02 XSS 0x03 SQL Injection 0x04 Vendor Notification ##### 0x01 Description ## ...